logo

Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek

ID: 047d45b3-eb20-53e8-8fc4-5808f868595c

STIX ID: report--047d45b3-eb20-53e8-8fc4-5808f868595c

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2025-01-30

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Wiz discovered a publicly accessible, unauthenticated ClickHouse instance tied to DeepSeek that exposed more than a million log entries containing plaintext chat history, API secrets, backend details, timestamps, and operational metadata. The database allowed arbitrary SQL via an HTTP /play endpoint, giving the potential for full control and privilege escalation; DeepSeek patched the issue after being informed, and regulators in Europe are investigating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.